Tooljet · Tooljet · CVE-2026-82872
**Name of the Vulnerable Software and Affected Versions**
ToolJet versions prior to 3.16.208
**Description**
Insufficient validation occurs when checking if the path `organizationId` matches the authenticated user's workspace during ToolJet DB table operations. This allows a workspace administrator to create, view, and delete database tables in a different workspace by modifying the `organizationId` parameter in table-management API requests.
**Recommendations**
Update to version 3.16.208 or later.